This is your work, valued
天苍苍,野茫茫,风吹的我就像头羊~ @0-sec && @pwnwiki-project && @xiecat
exphub. Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340
4.3kvulmap. Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能
3.5kdismap. Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
2.2kCVE-2021-3129. Laravel <= v8.4.2 debug mode: Remote code execution (CVE-2021-3129)
163logmap. Log4j jndi injection fuzz tool
70shiro-1.2.4-rce. shiro <= 1.2.4 反序列化远程命令执行利用脚本
52CVE-2021-4034. polkit pkexec Local Privilege Vulnerability to Add custom commands
45CVE-2020-10199_POC-EXP. CVE-2020-10199 Nexus <= 3.21.1 远程代码执行脚本(有回显)
43cobalt-strike. Resources About Cobalt Strike. 100+ Tools And 200+ Posts.
29Goby-PoC. some goby poc
15CVE-2020-5902. F5 BIG-IP 任意文件读取+远程命令执行RCE
13CVE-2020-10204. CVE-2020-10204 远程命令执行脚本
13zhzyker.
12Scanners-Box. A powerful hacker toolkit collected more than 10 categories of open source scanners from Github - 安全行业从业者自研开源扫描器合辑
11RedTeamTools. 记录自己编写、修改的部分工具
11Log4j2Passive. Log4j2 RCE Passive Scanner plugin for BurpSuite
10CVE-2020-11444. Nexus 3 越权漏洞利用脚本
10my-speech. 我的演讲 ppt or pdf 归档库
9sec-chart. 安全思维导图集合
9CVE-2018-7600-Drupal-POC-EXP. CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
8phpshell. php大马|php一句话|webshell|免杀过狗|渗透|黑客
8yougar0.github.io. 漏洞知识库
72021_Hvv. 2021 hw
7taowu-cobalt-strike. PowerShell
6goon. goon,是一款基于golang开发的扫描工具,暂时支持portscan、webscan、titlescan、dirscan、fofascan、pluginscan等模块功能,当然也支持将这些模块联动起来的autoscan。后期也会慢慢加入其他零件模块,感谢您的使用,也希望您能提供宝贵意见。
6PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
6AliyunAccessKeyTools. 阿里云AccessKey泄漏利用工具
5shiro_attack. shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)
4FourEye. AV Evasion Tool For Red Team Ops
4goblin. 一款适用于红蓝对抗中的蜜罐和钓鱼系统
4vulnx. vulnx 🕷️ is an intelligent bot auto shell injector that detect vulnerabilities in multiple types of cms { `wordpress , joomla , drupal , prestashop .. `}
4OneForAll. OneForAll是一款功能强大的子域收集工具
3HowToCook. 程序员在家做饭方法指南。Programmer's guide about how to cook at home (Chinese).
2GobyVuls. Vulnerabilities of Goby supported with exploitation.
2shiro-exploit. Shiro反序列化利用工具,支持新版本(AES-GCM)Shiro的key爆破,配合ysoserial,生成回显Payload
2CVE-2020-0787-EXP-ALL-WINDOWS-VERSION. Support ALL Windows Version
2CVE-2021-3156.
1SpringBootVulExploit. SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
1Prepare-for-AWD. AWD攻防赛脚本集合
1titan. Titan: A generic user defined reflective DLL for Cobalt Strike
1JNDIExploit. 对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改
1loading. A collection of highly customisable loading bars for Go CLI apps.
1Dict. 一些弱口令、fuzz字典
1linux-exploit-suggester. Linux privilege escalation auditing tool
1Goby. Attack surface mapping
1